Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2780▲ 24 respecto a la semana anterior
Críticas / altas1288▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
4643 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.51% | — | Adobe Experience ManagerAdobe Experience Manager Cloud Service | 15/6/2023 | 17/6/2026 | Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. | |
| Modificada | Alta (7.8) | 0.16% | — | Schneider-electric Ecostruxure Foxboro DCS Control Core Services | 14/6/2023 | 17/6/2026 | A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an unpredictable index to an IOCTL call in the Foxboro.sys driver. | |
| Modificada | Alta (7.8) | 0.19% | — | Schneider-electric Ecostruxure Foxboro DCS Control Core Services | 14/6/2023 | 17/6/2026 | A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | |
| Modificada | Media (4.7) | 0.38% | — | Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services | 13/6/2023 | 17/6/2026 | The underlying feedback mechanism of Rockwell Automation's FactoryTalk System Services that transfers the FactoryTalk Policy Manager rules to relevant devices on the network does not verify that the origin of the communication is from a legitimate local client device. This may allow a threat actor to craft a malicious… | |
| Modificada | Media (5) | 0.20% | — | Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services | 13/6/2023 | 17/6/2026 | Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected. Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives. This vulnerability may allow a local, authenticated non-admin user to craft a… | |
| Modificada | Alta (8.2) | 0.20% | — | Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services | 13/6/2023 | 17/6/2026 | Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies. Hard-coded cryptographic key may lead to privilege escalation. This vulnerability may allow a local, authenticated non-admin user to generate an invalid administrator cookie giving them… | |
| Modificada | Media (6.5) | 1.8% | — | Servicenow | 13/6/2023 | 17/6/2026 | ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: If this ACL bypass issue were to be successfully exploited, it potentially could allow an… | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Oretnom23 Service Provider Management System | 12/6/2023 | 17/6/2026 | Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2 | |
| Modificada | Media (6.5) | 0.94% | — | Redhat Openshift API FOR Data ProtectionRedhat Openshift Container PlatformRedhat Openshift Developer Tools AND Services | 6/6/2023 | 17/6/2026 | A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array,… | |
| Modificada | Alta (7.2) | 0.69% | — | Oretnom23 Service Provider Management System | 6/6/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad, clasificada como crítica, en SourceCodester Service Provider Management System v1.0. Esto afecta a una parte desconocida del archivo "view_service.php". La manipulación del argumento "id" conduce a una inyección SQL. Es posible iniciar el ataque de forma remota. La explotación ha… | |
| Modificada | Alta (8.8) | 0.73% | — | Oretnom23 Service Provider Management System | 6/6/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad, clasificada como crítica, en SourceCodester Service Provider Management System v1.0. Este problema afecta a una funcionalidad desconocida del archivo "view.php". La manipulación del argumento "id" conduce a una inyección SQL. El ataque puede ser lanzado remotamente. La… | |
| Modificada | Media (6.1) | 0.62% | — | Local Service Search Engine Management System Project Local Service Search Engine Management System | 31/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_area of the component POST Parameter Handler. The manipulation of the argument area with the input… | |
| Modificada | Media (5.4) | 0.38% | — | Servicenow | 23/5/2023 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbitrary scripts. | |
| Modificada | Media (4.9) | 0.72% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid… | |
| Modificada | Media (4.9) | 0.77% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid… | |
| Modificada | Media (4.9) | 0.40% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,… | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,… | |
| Modificada | Media (4.9) | 0.49% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Administrator… | |
| Modificada | Media (6.7) | 0.22% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Administrator… | |
| Modificada | Alta (7.2) | 1.1% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more… | |
| Modificada | Alta (7.2) | 1.1% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more… | |
| Modificada | Baja (3.8) | 0.37% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,… | |
| Modificada | Media (6.5) | 0.84% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these… | |
| Modificada | Media (6.5) | 0.84% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these… | |
| Modificada | Alta (8.8) | 0.73% | — | Oretnom23 Service Provider Management System | 17/5/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Service Provider Management System 1.0. This affects an unknown part of the file /classes/Master.php?f=delete_service. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… |